Missing User Warnings
Medium
- Confidence
- 90% confidence
- Finding
- The README instructs users to place a long-lived Access Token in a plaintext local config file under their home directory, but gives no warning about credential sensitivity, file permissions, rotation, or exclusion from backups/version control. That increases the chance of accidental disclosure through shared machines, backups, screenshots, shell history, or permissive filesystem access, which could allow unauthorized use of the TTS service.
